Техническая информация
- [HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'winpol' = '<SYSTEM32>\winpol.exe'
- [HKLM\System\CurrentControlSet\Services\Spooler Serivce] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\Spooler Serivce] 'ImagePath' = '<SYSTEM32>\winpol.exe'
- 'Spooler Serivce' <SYSTEM32>\winpol.exe
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\winpol.exe